From fedea097119058e1b8e5b3aad46767f354fb8493 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 1 Oct 2026 07:21:48 +0000 Subject: [PATCH 1/3] chore(deps-dev): bump js-yaml Bumps the dev-dependencies group with 1 update: [js-yaml](https://github.com/nodeca/js-yaml). Updates `js-yaml` from 5.4.1 to 5.4.2 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](https://github.com/nodeca/js-yaml/compare/5.4.1...5.4.2) --- updated-dependencies: - dependency-name: js-yaml dependency-version: 5.4.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies ... Signed-off-by: dependabot[bot] --- package-lock.json | 8 ++++---- package.json | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package-lock.json b/package-lock.json index b9d59a8d..651d94b9 100644 --- a/package-lock.json +++ b/package-lock.json @@ -18,7 +18,7 @@ "@types/js-yaml": "^4.0.9", "@types/node": "^22.10.0", "esbuild": "^0.28.2", - "js-yaml": "^5.4.1", + "js-yaml": "^5.4.2", "typescript": "^5.7.0", "vitest": "^4.1.11" }, @@ -1743,9 +1743,9 @@ } }, "node_modules/js-yaml": { - "version": "5.4.1", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-5.4.1.tgz", - "integrity": "sha512-28R/k+NAjeuf7+CKlTxWZVExJGwVVLwY06DgEnOMz2gEpfNkDcD7QvyiVPT0xy0XXhU8vHsd4Ot42OOPdJG7dQ==", + "version": "5.4.2", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-5.4.2.tgz", + "integrity": "sha512-m+aqu+LwO1O6sIopafj8HUVl5aawITwZQe/yHpMCKjaWBaA/d07B/QdMb3529REftiU+RMMHL3Vlsw3hON7vWg==", "dev": true, "funding": [ { diff --git a/package.json b/package.json index 531a1299..b13033db 100644 --- a/package.json +++ b/package.json @@ -50,7 +50,7 @@ "@types/js-yaml": "^4.0.9", "@types/node": "^22.10.0", "esbuild": "^0.28.2", - "js-yaml": "^5.4.1", + "js-yaml": "^5.4.2", "typescript": "^5.7.0", "vitest": "^4.1.11" }, From 280692b9348a9736b429e0c0e6b7468c7153bf7b Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 1 Oct 2026 07:22:00 +0000 Subject: [PATCH 2/3] chore(deps): bump @modelcontextprotocol/sdk from 1.30.0 to 1.30.1 Bumps [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) from 1.30.0 to 1.30.1. - [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases) - [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/1.30.0...1.30.1) --- updated-dependencies: - dependency-name: "@modelcontextprotocol/sdk" dependency-version: 1.30.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- package-lock.json | 8 ++++---- package.json | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package-lock.json b/package-lock.json index b9d59a8d..8db10d89 100644 --- a/package-lock.json +++ b/package-lock.json @@ -9,7 +9,7 @@ "version": "1.7.2", "license": "MIT", "dependencies": { - "@modelcontextprotocol/sdk": "^1.30.0", + "@modelcontextprotocol/sdk": "^1.30.1", "ajv": "^8.20.0", "ajv-formats": "^3.0.1", "commander": "^15.0.0" @@ -488,9 +488,9 @@ "license": "MIT" }, "node_modules/@modelcontextprotocol/sdk": { - "version": "1.30.0", - "resolved": "https://registry.npmjs.org/@modelcontextprotocol/sdk/-/sdk-1.30.0.tgz", - "integrity": "sha512-xKd8OIzlqNzcqcNumGAa6g+PW2kjD5vrpcKOnfldAUPP3j7lnqMPwlTXQm8gF+UwH72z0lqaRbjr9hqGz0eITA==", + "version": "1.30.1", + "resolved": "https://registry.npmjs.org/@modelcontextprotocol/sdk/-/sdk-1.30.1.tgz", + "integrity": "sha512-H2HxLvC3HDNybePJaLdSrU1hhUK5iQw+WvV1b01myFyI7sdVGe1u/IPTE5D9fGCiJDVtgMV/lmFkQXLmQyIFYA==", "license": "MIT", "dependencies": { "@hono/node-server": "^1.19.9 || ^2.0.5", diff --git a/package.json b/package.json index 531a1299..00fe6573 100644 --- a/package.json +++ b/package.json @@ -55,7 +55,7 @@ "vitest": "^4.1.11" }, "dependencies": { - "@modelcontextprotocol/sdk": "^1.30.0", + "@modelcontextprotocol/sdk": "^1.30.1", "ajv": "^8.20.0", "ajv-formats": "^3.0.1", "commander": "^15.0.0" From d703e48ea0f605c00b086b71efbaf6f531e9443c Mon Sep 17 00:00:00 2001 From: "commitlore-canonical-build[bot]" <317873099+commitlore-canonical-build[bot]@users.noreply.github.com> Date: Sat, 3 Oct 2026 09:03:37 +0000 Subject: [PATCH 3/3] Rebuild the canonical bundle for #1156 `build:canonical` on the merged tree, so the commit that lands matches the source it lands with. The pull request carried source only, which is what a contributor on a host that cannot run a linux/amd64 Docker build can produce (#720). Limit: this proves the bundle matches this tree; whether this tree is what a reviewer wants is what the pull request is for Blast: system Undo: easy Certainty: firm Record-Id: r-canonmerge1156 Provenance: authored Verified: artifact:verify passed against the regenerated manifest in the same job, before any credential was available to it CommitLore-Version: 2.0.0 --- installer/canonical-artifact.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/installer/canonical-artifact.json b/installer/canonical-artifact.json index a07498c4..2535efb9 100644 --- a/installer/canonical-artifact.json +++ b/installer/canonical-artifact.json @@ -15,7 +15,7 @@ "tsconfig.json", "src" ], - "sha256": "85d4e719a8a1a3302c30b080ad019d0c1dabc7bbf2284e685f20caed6aaa9ff2" + "sha256": "77fa87b6c582e68281004d4d098563652b138e81ff64e290c7c1b7288a222368" }, "artifact": { "sha256": "148696fcc3cda54db7e539c2cb63ab40eebc325e7ff5c2ab7c82a8599ed75e8b",